تخطَّ إلى المحتوى
QuenchWorks

ghost 0.0.12

مخطط · Apps & productivity · standard · v0.0.12

مثبّتة بالبصمةموقّعة بـ cosignSPDX SBOMمنشأ SLSAamd64 · arm64

Open-source Node.js publishing platform for blogs, newsletters, and membership sites. Packaged from Ghost's official npm distribution on a hardened Wolfi Node 22; configured entirely via environment and backed by an external MySQL/MariaDB with a content PVC for themes, images, and data.

الإصدار

يعيش الخط الأحدث في الصفحة الأساسية؛ وللخطوط الأقدم صفحاتها الخاصة لتتمكّن من تثبيت ذلك الإصدار بالضبط والتحقق منه. تُدرج الإصدارات الأحدث فقط — فالمخطط الأقدم يثبّت بصمة صورة أقدم.

إصدار صادر

هذا هو إصدار 0.0.12 من مخطط ghost ، نُشر بتاريخ 2026-08-27. للاطّلاع على تقرير الأمان الحي وبصمة الصورة المنشورة حاليًا، راجع أحدث إصدار.

موقّعة
cosign بدون مفتاح
SBOM
SPDX، على الصورة
المنشأ
بناء SLSA
المعماريات
amd64، arm64
تعمل كـ
nonroot (uid 1001)
نظام الملفات الجذر
للقراءة فقط

تقرير الأمان (Trivy)

D· 0/10023 fixable · rebuild clears them

تفاصيل الثغرات

ghost 6.57.1 · 30 CVE
الثغرة (CVE)الخطورةالحزمةالإصدار المثبَّتمُصلَحة فيالوصف
CVE-2026-75899HIGHfast-uri3.1.52.4.5, 3.1.6, 4.1.3fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding
CVE-2026-75931HIGHfast-uri3.1.52.4.5, 3.1.6, 4.1.3fast-uri: fast-uri: Host confusion via skipped IDN canonicalization
CVE-2026-75975HIGHfast-uri3.1.52.4.5, 3.1.6, 4.1.3fast-uri: fast-uri: Server-side request forgery via malformed IPv6 normalization
CVE-2026-76172HIGHfast-uri3.1.52.4.5, 3.1.6, 4.1.3fast-uri: fast-uri: URI parsing flaw enables server-side request forgery and redirects
CVE-2026-77037HIGHmulter2.2.02.3.0multer vulnerable to Denial of Service via file descriptor leak on aborted uploads
CVE-2026-77078HIGHmulter2.2.02.3.0multer vulnerable to Denial of Service via crafted multipart field names
CVE-2026-82333HIGHmulter2.2.02.3.0multer vulnerable to Denial of Service via oversized array index in field names
CVE-2026-84375HIGHjs-yaml4.3.14.3.2, 3.15.2js-yaml: js-yaml: Denial of Service vulnerability in YAML parsing
GHSA-2x7j-588g-ccc2HIGHnodemailer9.0.19.1.0Nodemailer: Quadratic (O(n²)) time complexity in addressparser allows remote denial of service via a crafted address list
GHSA-rgj7-g3m4-5g8cHIGHsharp0.35.30.35.4sharp: Vulnerabilities in libheif: GHSA-g89c-p67h-r497 and GHSA-2jg2-4ch7-h545
CVE-2020-8203HIGHlodash.pick4.4.0غير قابلة للإصلاحnodejs-lodash: prototype pollution in zipObjectDeep function
CVE-2022-37620HIGHhtml-minifier4.0.0غير قابلة للإصلاحkangax html-minifier REDoS vulnerability
CVE-2025-71329HIGHimage-size1.2.1غير قابلة للإصلاحimage-size: image-size: Denial of Service via crafted image buffer with zero-valued size field
CVE-2025-71330HIGHimage-size1.2.1غير قابلة للإصلاحimage-size: image-size: Denial of Service via crafted ICNS image buffer
CVE-2026-19693HIGHextract-zip2.0.1غير قابلة للإصلاحextract-zip: extract-zip: Arbitrary file write via symlink in archive
CVE-2026-56876HIGHextract-zip2.0.1غير قابلة للإصلاحextract-zip: github.com/maxogden/extract-zip: extract-zip: Arbitrary file write and information disclosure via symlink validation bypass
CVE-2026-18374MEDIUMglibc-2.442.44-r12.44-r6glibc: glibc: Heap buffer overflow via attacker-controlled fopen mode string
CVE-2026-18374MEDIUMglibc-2.44-locale-posix2.44-r12.44-r6glibc: glibc: Heap buffer overflow via attacker-controlled fopen mode string
CVE-2026-18374MEDIUMld-linux-2.442.44-r12.44-r6glibc: glibc: Heap buffer overflow via attacker-controlled fopen mode string
CVE-2026-63670MEDIUMsanitize-html2.17.52.17.6ApostropheCMS: Mutation-XSS / allowedTags bypass via literal `</textarea/>` solidus close
CVE-2026-82417MEDIUMqs6.15.36.16.0qs: qs: Denial of Service via improper validation in stringify function
CVE-2026-82562MEDIUMqs6.15.36.16.0qs: qs: Denial of Service via array limit bypass in query string parsing
CVE-2026-84371MEDIUMsanitize-html2.17.52.17.7sanitize-html: stored XSS via SVG SMIL URI-list scheme-policy bypass
CVE-2026-85091MEDIUMzlib1.3.2-r41.3.3-r0zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vul ...
GHSA-8m3c-c648-2xjjMEDIUMnodemailer9.0.19.1.1Nodemailer: resolveContent() on a MailMessage bypasses disableFileAccess/disableUrlAccess when called with the legacy signature
GHSA-cc9r-2j5m-2m83MEDIUMnodemailer9.0.19.1.0Nodemailer: Recipient-domain validation bypass via RFC 5322 comment mis-parsing leads to email delivery to an attacker-controlled domain
GHSA-rgwj-5xj2-c3m3MEDIUMmysql23.22.53.23.1MySQL2: Unbounded zlib inflate in compressed MySQL protocol handler allows decompression-bomb DoS
GHSA-wmmp-3585-3rmpMEDIUMnodemailer9.0.19.1.0Nodemailer: IDN/Punycode domain allow-list bypass leads to email delivery to an attacker-controlled domain
GHSA-984p-xq9m-4rjwMEDIUMexpress-brute1.0.1غير قابلة للإصلاحRate Limiting Bypass in express-brute
CVE-2026-77063LOWmulter2.2.02.3.0multer vulnerable to file size limit bypass via async fileFilter race condition
0
حرجة
16
عالية
13
متوسطة
1
منخفضة
0
غير معروفة

تقرير الأمان (Trivy) · image ghost 6.57.1

ثبّت المخطط

انشر إلى Kubernetes بإعدادات افتراضية مُحصّنة. يثبّت المخطط صورته ببصمة موقّعة، فلا تتعقّبها بنفسك أبدًا.

تثبيت (مثبّت على 0.0.12)

helm install my-ghost oci://ghcr.io/quenchworks/charts/ghost --version 0.0.12
إصدار المخطط
0.0.12
رخصة المخطط
MIT
رخصة التطبيق
MIT
منفذ الخدمة
2368
موقّع
cosign (بدون مفتاح)
صدر
2026-08-27

تحقّق من المخطط

cosign verify ghcr.io/quenchworks/charts/ghost:0.0.12 \
  --certificate-identity-regexp 'https://github.com/quenchworks/.+' \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com

الشفافية

يَنشُر المخطط شهاداته على GitHub ، والصورة التي ينشرها تحمل شهاداتها على البصمة نفسها، قابلة للتحقق علنًا بالأوامر أعلاه. كلاهما يُسجَّل في سجلّ شفافية Sigstore (Rekor)، الذي يفحصه cosign verify نيابةً عنك.

المشروع المنبع: https://ghost.org